Displaying TCAM Information for ACLs

You can use different forms of the show access-list tcam command to display information on the following items:

  • IPv4 ACLs
  • IPv6 ACLs
  • MAC ACLs
  • ACLs applied to the CPU
  • ACLs applied to an interface or LAG
  • ACLs applied to a stack unit
  • ACLs applied to incoming traffic
  • ACLs applied to outbound traffic
  • Statistics on ACL rules stored in TCAM
  • TCAM group types

Refer to the following examples for more information.

The following example provides TCAM information for the IPv4 ACL named 136. The show access-list tcam acl-name command shows which ports have the ACL programmed in TCAM, the type of ACL, which direction the ACL is applied, and how many rules, including the default rule, are programmed in TCAM for the ACL.

device(config-vlan-222)# show access-list tcam acl-name 136
Ingress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 1123  2125  1003    YES        1      e 1/1/18
2      UACL-IPv4 1123  2125  1003    YES        1      e 2/1/18

The following example provides detailed information for the same ACL. The detailed information includes ACL rules and associated ACL sequence numbers and ports.

device(config-vlan-222)# show access-list tcam acl-name 136 detail
Ingress:
UnitId Region Feature   Filter ID Rule  RefCnt Bind If
------ ------ -------   --------- ----- ------ -------
1      0      UACL-IPv4  8        1123  1      e 1/1/18
1      0      UACL-IPv4 10        1124  1      e 1/1/18
1      0      UACL-IPv4 20        1125  1      e 1/1/18
1      0      UACL-IPv4 30        1126  1      e 1/1/18
1      0      UACL-IPv4 40        1127  1      e 1/1/18
1      0      UACL-IPv4 50        1128  1      e 1/1/18
1      0      UACL-IPv4 60        1129  1      e 1/1/18
1      0      UACL-IPv4 70        1130  1      e 1/1/18
1      0      UACL-IPv4 80        1131  1      e 1/1/18
...

The following example displays the VLAN 333 configuration information on TCAM rules for the IPv6 ACL named vlan333-ipv6.

device(config-vlan-333)# show running-config vlan 333                       
vlan 333 by port
 tagged ethe 1/1/10 ethe 2/1/10 ethe 3/1/10 lag 25 
 interface ve 333
 ipv6 access-group vlan333-ipv6 in  <-- Applied VLAN shown in output
mac access-group mac_acl in
 ip access-group vlan333-ipv4 in
 ip access-group frag deny
!
!
device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6
Ingress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If                                           
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv6 641   786   146     YES        1      e 1/1/10
2      UACL-IPv6 1012  1157  146     YES        2      e 2/1/10 e 2/1/38
3      UACL-IPv6 1147  1292  146     YES        2      e 3/1/10 e 3/1/40

The following example shows detailed TCAM information for the same IPv6 ACL.

device(config-vlan-333)# show access-list tcam acl-name vlan333-ipv6 detail 
Ingress:
UnitId Region Feature         Filter ID Rule  RefCnt Bind If                                           
------ ------ -------         --------- ----- ------ -------                                           
1      0      UACL-IPv6       1         641   1      e 1/1/10                                          
1      0      UACL-IPv6       2         642   1      e 1/1/10                                          
1      0      UACL-IPv6       3         643   1      e 1/1/10                                          
1      0      UACL-IPv6       6         644   1      e 1/1/10                                          
1      0      UACL-IPv6       12        645   1      e 1/1/10                                          
1      0      UACL-IPv6       13        646   1      e 1/1/10                                          
1      0      UACL-IPv6       14        647   1      e 1/1/10      

The following example breaks out TCAM rule information for a MAC ACL found in the running configuration for VLAN 333.

device(config-vlan-333)# show access-list tcam acl-name mac_acl
Ingress:
UnitId Feature         SRule ERule Filters Contiguous RefCnt Bind If                                           
------ -------         ----- ----- ------- ---------- ------ -------                                           
1      UACL-MAC        1119  1129  11      YES        1      e 1/1/10                                          
2      UACL-MAC        1490  1500  11      YES        2      e 2/1/10 e 2/1/38                                 
3      UACL-MAC        1625  1635  11      YES        2      e 3/1/10 e 3/1/40                                 
device(config-vlan-333)# show access-list tcam acl-name mac_acl detail 
Ingress:
UnitId Region Feature         Filter ID Rule  RefCnt Bind If                                           
------ ------ -------         --------- ----- ------ -------                                           
1      0      UACL-MAC        10        1119  1      e 1/1/10                                          
1      0      UACL-MAC        20        1120  1      e 1/1/10                                          
1      0      UACL-MAC        30        1121  1      e 1/1/10                                          
1      0      UACL-MAC        40        1122  1      e 1/1/10                                          
1      0      UACL-MAC        50        1123  1      e 1/1/10                                          
1      0      UACL-MAC        60        1124  1      e 1/1/10                                          
1      0      UACL-MAC        70        1125  1      e 1/1/10                                          
1      0      UACL-MAC        80        1126  1      e 1/1/10                                          
1      0      UACL-MAC        90        1127  1      e 1/1/10                                          
1      0      UACL-MAC        100       1128  1      e 1/1/10                                          
1      0      UACL-MAC        65001     1129  1      e 1/1/10                                          
2      0      UACL-MAC        10        1490  2      e 2/1/10 e 2/1/38                             

The following example displays TCAM usage for a specified stack unit. Information includes available TCAM space for IPv4, IPv6, and MAC ACLs. For a dual-PP device, the command output includes information on the region (0 or 1).

device# show access-list tcam usage unit 4
UnitId Region Group Id Direction  Type            :            Allocated Total Free
------ ------ -------- ---------  ----            :            --------- ----- ----
4      0      1        Pre-Ingres L2_IPv4 Filters :            1         512   511
4      0      2        Pre-Ingres VCAP_MISC       :            0        1024  1024
4      0      3        Ingress    IPv4 Filters    :            9        2816  2807 
4      0      4        Ingress    IPv6 Filters    :            0        1408  1408 
4      0      5        Ingress    L2 Filters      :           30        2816  2786 
4      0      6        Ingress    ICAP All Combo  :           51         768   717
4      0      7        Ingress    IPSec Filters   :            0        1408  1408
4      0      8        Egress     IPv4 Filters    :            0         256   256 
4      0      9        Egress     IPv6 Filters    :            0         256   256 
4      0     10        Egress     L2 Filters      :            3         256   253 
4      1      1        Pre-Ingres L2_IPv4 Filters :            1         512   511
4      1      2        Pre-Ingres VCAP_MISC       :            0        1024  1024
4      1      3        Ingress    IPv4 Filters    :         1031        2816  1785 
4      1      4        Ingress    IPv6 Filters    :            7         896   889 
4      1      6        Ingress    ICAP All Combo  :           51         512   461
4      1      7        Ingress    IPSec Filters   :            0         896   896
4      1      8        Egress     IPv4 Filters    :            4         256   252
4      1      9        Egress     IPv6 Filters    :          247         256     9
4      1     10        Egress     L2 Filters      :            3         256   253

The following example displays TCAM information for a specified interface. Use this command to verify ACLs applied on an interface and how many filters are programmed in TCAM for each ACL.

device# show access-list tcam interface ethernet 4/1/10
Ingress:
UnitId AclName      Feature    SRule ERule  Filters Contiguous Merged Acl
------ -------      -------    ----- -----  ------- ---------- ---------
4      STK_ZTP_0403 ZTP         36    36    1       YES
4      STK_IPC_0401 STK_HIGIG    5     5    1       YES
4      123          UACL-IPv4   84   104   21       YES
4      mac_acl      UACL-MAC   105   115   11       YES

Egress:
UnitId AclName      Feature    SRule ERule Filters Contiguous Merged Acl
------ -------      -------    ----- ----- ------- ---------- ---------
4      140          UACL-IPv4  128   129    2      YES
4      egress       UACL-IPv6  118   127   10      YES

The following example displays more detailed information for the same interface, including all rules and filters (by sequence number) for each ACL bound to the interface.

device# show access-list tcam interface ethernet 4/1/10 detail
Ingress:
UnitId Region AclName        Feature     Filter Id Rule
------ ------ -------        -------     --------- -----
4      1      STK_ZTP_0403   ZTP         1         36
4      1      STK_IPC_0401   STK_HIGIG   1          5
4      1      123            UACL-IPv4  10         84
4      1      123            UACL-IPv4  20         85
4      1      123            UACL-IPv4  30         86
4      1      123            UACL-IPv4  40         87
4      1      123            UACL-IPv4  50         88
...

The following example displays TCAM information for a specified LAG interface.

device# show access-list tcam interface lag 8060
Ingress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      qos_dscp_34 QOS-DSCP/PCP   909    909  1       YES
3      qos_dscp_34 QOS-DSCP/PCP   907    907  1       YES

Egress:
UnitId AclName     Feature       SRule  ERule Filters Contiguous Merged Acl
------ -------     -------       -----  ----- ------- ---------- ---------
2      125         UACL-IPv4      1587   1822 236     YES
2      egress      UACL-IPv6      1823   2026 204     YES
3      125         UACL-IPv4      1585   1820 236     YES
3      egress      UACL-IPv6      1821   2024 204     YES

The following example displays detailed information for a specified LAG.

device# show access-list tcam interface lag 8060 detail
Ingress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      qos_dscp_34 QOS-DSCP/PCP 10        909
3      0      qos_dscp_34 QOS-DSCP/PCP 10        907

Egress:
UnitId Region AclName     Feature      Filter Id Rule
------ ------ -------     -------      --------- -----
2      0      125         UACL-IPv4      2       1587
2      0      125         UACL-IPv4    110       1588
2      0      125         UACL-IPv4    120       1589

The following example displays TCAM information for ACLs applied in an outbound direction on unit 1. The command output shows all ACLs programmed in TCAM for the specified unit in the specified direction, including system default rules.

device# show access-list tcam egress unit 1
Egress:
UnitId AclName           Feature    SRule ERule Filters Contiguous RefCnt Bind If
------ -------           -------    ----- ----- ------- ---------- ------ -------
1      ECPU_PORTID_RULE  CPU_RULES   84    85   2       YES        1
1      ECPU_CLASSID_RULE CPU_RULES   86    86   1       YES        1

The show access-list tcam rule-statistics command is used to display hardware-level accounting statistics. The output is displayed for a specific rule in a specific region on a specific unit.

device# show access-list tcam rule-statistics 3161 unit 1 region 0
Rule: 3161 Stat: 0

The show access-list tcam rule command displays output for a specific rule programmed in TCAM. The command is local to each unit. The following example displays information on rule 3161 for region 0 of unit 1.

device# show access-list tcam rule 3161 unit 1 region 0
EID 0x00000c59: gid=0x3,
slice=0, slice_idx=0xc9, part =0 prio=0x1fe0216, flags=0x210602, Installed, Enabled
tcam: color_indep=1,
StageIngress
InPorts
DATA=0x0000000000000000000000000000000000000000000000000008000000000800
MASK=0x00000000000000000000000000000000000000000000000003fe000001ffffff
Stage
IpType
Offset0: 325 Width0: 4
DATA=0x00000000
MASK=0x0000000e
InterfaceClassL2
Offset0: 32 Width0: 12
DATA=0x0000000e
MASK=0x00000fff
action={act=CosQCpuNew, param0=31(0x1f), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=SwitchToCpuCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=DynamicHgTrunkCancel, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
action={act=Drop, param0=0(0x00), param1=0(0x00), param2=0(0x00), param3=0(0x00)}
policer=
statistics={stat id 3079 slice = 6 idx=0 entries=1}{Packets}{Bytes}

The following example displays TCAM information for the ACL cpu-ipv4 applied to outgoing traffic on the CPU of the active controller for the stack.

device(config-if-cpu-active)# show access-list tcam acl-name cpu-ipv4
Egress:
UnitId Feature   SRule ERule Filters Contiguous RefCnt Bind If
------ -------   ----- ----- ------- ---------- ------ -------
1      UACL-IPv4 2218  2220  3       YES        1
2      UACL-IPv4 1250  1252  3       YES        1

The following example provides information for the icap-all-combo group type. The output includes the unit ID, ACL name, associated feature, start and end rule numbers, number of filters, filter contiguity status, reference count, and the bound interfaces.

device# show access-list tcam group icap-all-combo

UnitId AclName                Feature     SRule  ERule Filters Contiguous RefCnt Bind If
----- -------                 -------     -----  ----- ------- ---------- ------ -------
1    SFLOW_RULE               SFLOW       262145 262145 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-UDP-BC         UDP_BC      262146 262150 5       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-OSPFv2         OSPF        262151 262151 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-OSPFv3         OSPF        262152 262152 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-GRE            GRE         262153 262153 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-IPV6-RES-MC    IPV6_RES_MC 262154 262154 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-DDOS-TCP-SYN-IPV4 DA_MGMT     262195 262195 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    FLEXAUTH_802.1X_BPDU_RULE FLEXAUTH   262155 262155 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    ICMP-ECHO-BC             ICMP_BC     262196 262196 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-VRRP           VRRP        262156 262157 2       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYSTEM-L3-ND             ND          262158 262160 3       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4
1    SYS_DHCPV6_CLIENT       DHCPV6_CLIENT262197 262197 1       YES        52   e 1/1/1 to 1/1/48
                                                                                e 1/2/1 to 1/2/4